verify

Fail

Audited by Snyk on Jul 17, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill requires the agent to run arbitrary commands and "state the result, cite command, exit code, and key output" (and even shows a CLI with free-text content), which forces verbatim inclusion of command strings and outputs — risking exfiltration if those contain API keys, tokens, or passwords.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jul 17, 2026, 11:08 AM
Issues
1
Security Audit — snyk — verify